
' TO OHAXffBOBbSED PERSON(B) 9 



FILE OK 
SERIAL. 
NUMBER 
AND 

SUBJECT 



■REF ID:A64 64 9 

KECOBDS CHARGE-OUT 



From File of Special Consultant (Friedman) 
Military Cryptanalysis 9 Part 1 
Serial 310.21 



-1 



TO 



HAKE MID EXTENSION OF PERSON REQUESTING FILE 



Mr. William Friedman LI6-8520 



ORGANIZATION, : 

1310 2nd,Str,SE, 



RETURN 

TO 



Mr e e Chrisjlan, AG-24*NSA,Ft .Geo •Gatfeade,Md# 



INSTRUCTIONS 



WHEN TRANSFESR3N0 FILS TO ANOTHER PERSON, COMPLETE 
LETTER-SIZE PAPER MID PLACE IN OUTOODKl HAIL 



TRANSFER CO 




eclassified and approved for release by NSA on 12-23-2013 
lursuantto E.Q. 13526 , 










REF ID:A64649 



3\ O. ?L\ 




I 




NATIONAL SECURITY AGENCY 



MILITARY CRYPTANALYTICS 

Part I 



WILLIAM F. FRIEDMAN 

to OHi. p an ^ 

LAMBROS D. CALLIMAHOS 

A^45 **• {A *yffe **‘y i |«>j inMOtJ)* tr>^« n i «. r ■-- 'Of’ A«w« 

^ J~sc *-yt, «. 

JiVj IT. ■ Ak*-4»t» J, 



NOTICE: This material contains information affecting the national defense of 
the United States within the meaning of the espionage laws. Title 18, U.S.C,, 
Secs. 793 and 794, the transmission or revelation of which in any manner tojan 
unauthorized person is prohibited by law. 




April 1956 




REF ID:A64649 



OO N nPE N TUL 



NSATL S-70,021 



The Golden Guess 
Is Morning-Star to the full round of Truth. 

— Tennyson. 



Preface 

This text represents an extensive expansion and revision, both in scope 
and content, of the earlier work entitled “Military Cryptanalysis, Part I” by 
William F. Friedman. This expansion and revision was necessitated by the 
considerable advancement made in the art since the publication of the previous 
text. 

I wish to express grateful acknowledgment for Mr. Friedman’s generous 
assistance and invaluable collaboration in the preparation of this volume. I 
also extend particular appreciation to my colleague Robert E. Cefail for his 
numerous valuable comments and assistance in writing the new material which 
is contained herein. 

— X. D. C. 

(n) 



IWH riDC N TIAt 



REF ID:A64649 



t ci t v 


B 


c. g e c e 


A 


G g <G V g 


c 


o v ✓ c v 


0 


G v v" c c 


M 


£ c. c v ✓ 


D 


g y c. e. g 


/-J 


c < c y y 


D 


c V V £ c 


A/ 


£. , y V c y 


a 


y c c y c 


T 


y c y c £ 


W 


v g c. c c 


7? 


£ V O C G 


/-J 


1/ G & ^ C 


r 


C £ * C C 


£" 


1/ C G ✓ £ 


r 


g g ✓ y y 


H 


c. v c. c c 


/-J 


v c c c y 


5 


V <- y c c 


W 


g v v c. y 


0 


/ g g c o 


R 


G V G G y 


K 




' X t^rx. Cr +-^4 
d-r^o *** dtt 

■€&€*+ 






■zts. 






V - 



- b 0 





RlEF ID:A64 64 9 



TABLE OF CONTENTS 
Military Cryptanalytics, Part I 
Monoalphabetic Substitution Systems 

Chapter Page 

I. Introductory remarks 1 

1. Scope of this text. 2. Mental equipment necessary for cryptanalytic work. 

3. Validity of results of cryptanalysis. 

II. Basic cryptologic considerations 9 

4. Cryptology, co mmuni cation intelligence, and communication security. 5. 

Secret communication. 6. Plain text and encrypted text. 7. Cryptography, 



encrypting, and decrypting. 8. Codes, ciphers, and enciphered code. 9. General 
system, specific key, and cryptosystem. 10. Cryptanalytics and cryptanalysis. 

11. Transposition and substitution. 12. Nature of alphabets. 13. Types of 
alphabets. 

HI. Fundamental cryptanalytic operations 17 

14. The role of cryptanalysis in communication intelligence operations. 15. 

The four basic operations in cryptanalysis. 16. The determination of the language 
employed. 17. The determination of the general system. 18. The reconstruction 
of the specific key. 19. The reconstruction of the plain text. 20. The utilization 
of traffic intercepts. 

IV. Frequency distributions and their fundamental uses 25 

21. The simple or uniliteral frequency distribution. 22. Important features 
of the normal uniliteral frequency distribution. 23. Constancy of the standard 
or normal uniliteral frequency distribution. 24. The three facts which can be 
determined from a study of the uniliteral frequency distribution for a cryptogram. 

25. Determining the class to which a cipher belongs. 26. Determining whether 
a substitution cipher is monoalphabetic or nonmonoalphabetic. 27. The <j> (phi) 
test for determining monoalphabeticity. 28. Determining whether a cipher alpha- 
bet is standard or mixed. 

V. Uniliteral substitution with standard cipher alphabets 45 

29. Types of standard cipher alphabets. 30. Procedure in encipherment and 
decipherment by means of uniliteral substitution. 31. Principles of solution by 
construction and analysis of the uniliteral frequency distribution. 32. Theoretical 
example of solution. 33. Practical example of solution by the frequency method. 

34. Solution by completing the plain-component sequence. 35. Special remarks 
on the method of solution by completing the plain-component sequence. 36. Value 
of mechanical solution as a short cut. 37. Basic reason for the low degree of 
cryptosecurity afforded by monoalphabetic cryptograms involving standard cipher 
alphabets. 

VI. Uniliteral substitution with mixed cipher alphabets 61 

38. Literal keys and numerical keys. 39. Types of mixed cipher alphabets. 

40. Additional remarks on cipher alphabets. 41. Preliminary steps in the analysis 
of a monoalphabetic, mixed-alphabet cryptogram. 42. Preparation of the work 
sheet. 43. Triliteral frequency distributions. 44. Classifying the cipher letters 
into vowels and consonants. 45. Further analysis of the letters representing vowels 



on) 







REF ID:A64649 



-C O HF ID ENTIAL - 

Chapter Page 

and consonants. 46. Substituting deduced values in the cryptogram. 47. Com- 
pleting the solution. 48. General remarks on the foregoing solution. 49. The 
“probable-word” method; its value and applicability. 50. Solution of additional 
cryptograms produced by the same components. 51. Recovery of key words. 

VII. Multiliteral substitution with single-equivalent cipher alphabets 91 

52. General types of multiliteral cipher alphabets. 53. The Baconian and 
Trithemian ciphers. 54. Analysis of multiliteral, monoalphabetic substitution 
ciphers. 55. Historically interesting examples. 56. The international (Baudot) 
teleprinter code. 

VUI. Multiliteral substitution with variants 103 

57. Purpose of providing variants in monoalphabetic substitution. 58. Simple 
types of cipher alphabets with variants. 59. More complicated types of cipher 
alphabets with variants. 60. Analysis of simple examples. 61. Analysis of more 
complicated examples. 62. Analysis involving the use of isologs. 63. Further 
remarks on variant systems. 

IX. Polygraphic substitution systems 129 

64. General remarks on polygraphic substitution. 65. Polygraphic substitu- 
tion methods employing large tables. 66. Polygraphic substitution methods em- 
ploying small matrices. 67. Methods for recognizing polygraphic substitution. 

68. General procedure in the identification and analysis of polygraphic substi- 
tution ciphers. 69. Analysis of four-square matrix systems. 70. Analysis of two- 
square matrix systems. 71. Analysis of Playfair cipher systems. 72. Analysis 
of polygraphic systems involving large tables. 73. Further remarks on polygraphic 
substitution systems. 

X. Cryptosystems employing irregular-length ciphertext units-. 189 

74. Preliminary observations. 75. Monome-dinome alphabets and other alpha- 
bets with irregular-length ciphertext units. 76. General remarks on analysis. 

77. Analysis of simple .examples. 78. Analysis of more complicated examples. 

79. Further remarks on cryptosystems employing irregular-length ciphertext units. 

XI. Miscellaneous monoalphabetic systems ; concluding remarks 209 

80. Cryptosystems employing syllabary squares and code charts. 81. Crypto- 
systems employing characters other than letters or figures. 82. Special remarks 
concerning the initial classification of cryptograms. 83. Disguised secret com- 



munications. 84. Concluding remarks. 

APPENDICES 

1. Glossary for Military Cryptanalytics, Part I 231 

2. Letter frequency data — English 247 

3. Word and pattern lists — English 289 

4. Service terminology and stereotypes 337 

5. Letter frequency data — foreign languages 347 

6. Classification guide to concealment systems 373 

7. Communication intelligence operations 379 

8. Principles of cryptosecurity 393 

PcpWems — Military Cryptanalytics, Part I 403 

- - 431 




REF ID:A64649 



"T fflfflBHHaH - 



Chapteb I 

INTRODUCTORY REMARKS 



Paragraph 

Scope of this text 1 

Mental equipment necessary for cryptanalytic Work 2 

Validity of results of cryptanalysis. — . 3 



1. Scope of this text. — a. This text constitutes the first of a series of six basic texts 1 on 
the science of cryptanaiytics and the art of cryptanalysis. Although most of the information 
contained herein is applicable to cryptograms of various types and sources, special emphasis 
will be laid upon the principles and methods of solving military 2 cryptograms. Except for an 
introductory discussion of fundamental principles underlying the science of cryptanaiytics, this 
first text in the series will deal solely with the principles and methods for the analysis of mono- 
alphabetic substitution ciphers. Even with this limitation it will be possible to discuss only a 
few of the many variations of this type that are met in practice; but with a firm grasp upon 
the general principles few difficulties should be experienced with any modifications or variations 
that may be encountered. 

b. This and the succeeding texts will deal with, among others, some basic types of cryptosys- 
tems not because they may be encountered unmodified in military operations but because their 
stutiy is essential to an understanding of the principles underlying the solution of the modern, very 
much more complex types of codes, ciphers, and certain encrypted transmission systems that 
are likely to be employed by the larger governments of today in the conduct of their military 
affairs in time of war. 

c. It is presupposed that the student has no prior background in the field of cryptology; 
therefore cryptography is presented concurrently with cryptanalysis. It is also presupposed 
that the reader has had but a minimal mathematical background; a student who has had 
elementary algebra should encounter no difficulty with the mathematical treatment in the 
body of the text, and he will be progressively guided into augmenting his mathematical back- 
ground to fit the needs of cryptanaiytics. Basic terminology and preliminary cryptologic con- 
siderations are treated in Chapter II; other terms are usually defined upon their first occurrence, 
or they may be found in the Glossary (Appendix 1). Footnotes, besides amplifying general 
information, include occasional treatment of mathematical principles that may be beyond a 
beginner in the field ; the student therefore should not spend too much time trying to assimilate 
all the information contained therein. 

d. The cryptograms presented in the examples embrace messages from hypothetical air, 
ground, and naval traffic; thus, the student will have the opportunity to familiarize himself 
with the language and phraseology of all three military Services. 



1 Each text has its accompanying course in cryptanalysis, so that the student may test his learning and 
develop his skill in the solution of the types of cryptograms treated in the respective texts. The problems which 
pertain to this text constitute Appendix 9. 

8 The word “military” is here used in its broadest sense. In this connection see subpar. d, below. 



1 



OO N FID E HTIAL 




REF ID:A64649 



BMtfl DElTHU. / 

2. Mental equipment necessary for cryptanalytic work. — a. Captain Parker Hitt, in the 
first United States Army manual 8 dealing with cryptology, opens the first chapter of his 
valuable treatise with the following sentence: 

"Success in dealing with unknown ciphers is measured by these four things in the order 
named: perseverance, careful methods of analysis, intuition, luck.” 

These words are as true today as they were then. There is no royal road to success in the 
solution of cryptograms. Hitt goes on to say: 

“Cipher work will have little permanent attraction for one who expects results at once, 
without labor, for there is a vast amount of purely routine labor in the preparation of frequency 
tables, the rearrangement of ciphers for examination, and the trial and fitting of letter to letter 
before the message begins to appear.” 

The author deems it advisable to add that the kind of work involved in solving cryptograms 
is not at all similar to that involved in solving crossword puzzles, for example. The wide vogue 
the latter have had and continue to have is due to the appeal they make to the quite common 
interest in mysteries of one sort or another; but in solving a crossword puzzle there is usually no 
necessity for performing any preliminary labor, and palpable results become evident after the 
first minute or two of attention. This successful start spurs the crossword “addict” on to com- 
plete the solution, which rarely requires more than an hour’s time. Furthermore, crossword 
puzzles are all alike in basic principles and once understood, there is no more to learn. Skill 
comes largely from the embellishment of one’s vocabulary, though, to be sure, constant practice 
and exercise of the imagination contribute to the ease and rapidity with which solutions are 
generally reached. In solving cryptograms, however, many principles must be learned, for there 
are many different systems of varying degrees of complexity. Even some of the simpler varieties 
require the preparation of tabulations of one sort or another which many people find irksome; 
moreover, it is only toward the very close of the solution that results in the form of intelligible 
text become evident. Often, indeed, the student will not even know whether he is on the right 
track until he has performed a large amount of preliminary “spade work” involving many hours 
of labor. Thus, without at least a willingness to pursue a fair amount of theoretical study, and a 
more than average amount oj patience and perseverance, little skill and experience can be gained in 
the rather difficult art of cryptanalysis. General Givierge, the author of an excellent treatise on 
cryptanalysis, remarks in this connection: 4 

“The cryptanalyst’s attitude must be that of William the Silent: 'No need to hope in order 
to undertake, nor to succeed in order to persevere’.” 

b. As regards Hitt’s reference to careful methods of analysis, before one can be said to be 
a cryptanalyst worthy of the name it is necessary that one should have, firstly, a sound knowl- 
edge of the basic principles of cryptanalysis, and secondly, a long, varied, and active practical 
experience in the successful application of those principles. It is not sufficient to have read 
treatises on this subject. One month’s actual practice in solution is worth a whole year’s mere 
reading of theoretical principles. An exceedingly important element of success in solving the 
more intricate cryptosystems is the possession of the rather unusual mental faculty designated 
in general terms as the power of inductive and deductive reasoning. Probably this is an inherited 
rather than an acquired faculty; the best sort of training for its emergence, if latent in the 
individual, and for its development is the study of the natural sciences, such as chemistry, 

* Hitt, Capt. Parker, Manual for the Solution of Military Ciphers. Army Service Schools Press, Fort 
Leavenworth, Kansas, 1916. 2d Edition, 1918. (Both out of print.) 

4 Givierge, G<5n6ral Marcel, Cours de Cryptographic, Paris, 1925, p. 301. 



OO N HDE N Tm 



2 



REF ID:A64649 



OWF I D i NTIAU 

physics, biology, geology, and the like. Other sciences such as linguistics, archaeology, and 
philology are also excellent. 

c. Aptitude in mathematics is quite important, more especially in the solution of ciphers 
and enciphered codes than in codebook reconstruction, which latter is purely and simply a 
linguistic problem. Although in the early days of the emergence of the science of cryptanalytics 
little thought was given to the applications of mathematics in this field, many branches of 
mathematics and, in particular, probability and statistics, have now found cryptologic applica- 
tions. Those portions of mathematics and those mathematical methods which have cryptologic 
applications 5 are known collectively as cryptomathematics. 

d. An active imagination, or perhaps what Hitt and other writers call intuition, is essential, 
but mere imagination uncontrolled by a judicious spirit will be more often a hindrance than 
a help. In practical cryptanalysis the imaginative or intuitive faculties must, in other words, 
be guided by good judgment, by practical experience, and by as thorough a knowledge of the 
general situation or extraneous circumstances that led to the sending of the cryptogram as is 
possible to obtain. In this respect the many cryptograms exchanged between correspondents 
whose identities and general affairs, commercial, social, or political, are known are far more 
readily solved • than are isolated cryptograms exchanged between unknown correspondents, 
dealing with unknown subjects. It is obvious that in the former case there are good data upon 
which the intuitive powers of the cryptanalyst can be brought to bear, whereas in the latter 
case no such data are available. Consequently, in the absence of such data, no matter how 
good the imagination and intuition of the cryptanalyst, these powers are of no particular service 
to him. Some writers, however, regard the intuitive spirit as valuable from still another view- 
point, as may be noted in the following : 7 

“Intuition, like a flash of lightning, lasts only for a second. It generally comes when 
one is tormented by a difficult decipherment and when one reviews in his min d the fruitless 
experiments already tried. Suddenly the light breaks through and one finds after a few minutes 
what previous days of labor were unable to reveal.” 



* It is quite important to stress at this point that in professional cryptologic work the science of cryptanalytics 
is subordinated to the art of cryptanalysis, just as in the world of music the technical virtuosity of a great 
violinist is adjuvant to the expression of music, that is, the virtuosity is a “tool” for the recovery of the complete 
musical “plain text” conceived by the composer. Since the practice of cryptanalysis is an art, mathematical 
approaches cannot always be expected to yield a solution in cryptology, because art can and must transcend 
the cold logic of scientific method. By way of example, an experienced Indian guide can usually find his way 
out of a dense forest more readily than a surveyor equipped with all the refined apparatus and techniques of 
his profession. Likewise, an experienced cryptanalyst can generally find his way through a cryptosystem 
more readily than a pure mathematician equipped merely with the techniques of his field no matter how abstruse 
or refined they may be. A cryptomathematician of repute once stated that “the only effect of [refined mathe- 
matical techniques] is frequently to discourage one so much that one does nothing at all and some unmathe- 
matical ignoramus then gets the problem out in some very unethical way. This is intensely irritating.” See 
also in this connection the remarks made in subpar. 27e in reference to the validity of statistical tests in crypt- 
analysis. 

* The application in practical, operational cryptanalysis of “probable words” or “cribs”, i. e., plain text 
assumed or known to be present in a cryptogram, is developed in time of war into a refinement the extent and 
usefulness of which cannot be appreciated by the uninitiated. Even as great a thinker as Voltaire found the 
subject of cryptanalysis stretching his credulity to the point that he said: 

“Those who boast that they can decipher a letter without knowing its subject matter, and without pre- 
liminary aid, are greater charlatans than those who would boast of understanding a language which they have 
never learned ." — Diclionnaire Phtlosophique, under the article “Poste". 

7 Lange et Soudart, TraiU de Cryptographic, Libraire F61ix Alcan, Paris, 1925, p. 104. 



s 



ooupiimiim — 

uunriucvviuiL 




